Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Seems to me you are not valuing the removal of a painful obstacle to business.

It is essentially a public type service. An investment.

Secondly, a bug bounty exists because of how disclosure works. Someone could camp on a bug and or sell it, use their knowledge of it to do nefarious, harmful and certainly expensive things.

There are actual risks too.

The bounty is an alternative to those actions. Responsible disclosure is encouraged (rewarded) in the hope bug hunters do the right things.

Prior art works very differently.

"Not Very expensive"

Maybe that is true. It seems hard to say. Both efforts can take considerable time.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: